#VU14377 Authentication bypass in Windows Server - CVE-2018-8340
Published: August 14, 2018 / Updated: August 14, 2018
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to bypass certain authentication factors.
The vulnerability exists due to an error when processing multi-factor authentication requests within Active Directory Federation Services (AD FS). A remote attacker can bypass certain authentication factors during multi-factor authentication and gain unauthorized access to sensitive data and functionality.